NSE Cyberattack: 395 Million Website Hits in 11 Minutes
NSE's website received approximately 395 million hits during an 11-minute distributed denial-of-service attack in May 2025. The exchange said the attack slowed its multilingual website page but did not materially affect operations, according to its red herring prospectus dated September 10, 2026.
The disclosure gives a specific example of the cyber threats facing market infrastructure. It also sets limits on what can be concluded from the incident: the RHP describes a website availability problem and does not identify the attack as a trading shutdown or a confirmed theft of investor data.
What happened during the NSE DDoS attack?
The cyber-risk section on pages 36–37 identifies a high-volume distributed denial-of-service, or DDoS, attack against NSE's website in May 2025. It records approximately 395 million hits in 11 minutes and a slowdown affecting the multilingual page.
In this type of incident, the immediate issue is the ability of a service to remain available under a heavy volume of incoming traffic. NSE's account focuses on the traffic volume and the observed slowdown.
The 395 million figure is a count of hits, rather than a count of unique attackers, affected investors or stolen records. The RHP does not provide evidence for converting it into any of those other measures.
The company also does not identify an attacker in the disclosure. Assigning responsibility to a named organisation or country would require evidence outside the supplied filing.
Did the attack stop trading or expose investor data?
NSE stated that the incident did not have a material impact on its operations. That is the company's account in the RHP, and it should remain attributed when the incident is reported.
The same risk section says that, apart from the highlighted DDoS attack, there were no uncontained or unmitigated cybersecurity incidents or data breaches in FY2024, FY2025, FY2026 and the three months ended June 30, 2026.
The wording is narrower than a claim that NSE never faced cyber incidents or attempted attacks. It also does not establish that every conceivable threat was prevented. The RHP explicitly describes continuing risks despite the controls in place.
What cybersecurity controls does NSE describe?
NSE describes itself as designated national Critical Information Infrastructure and reports continuous monitoring through its cyber defence centre. Its stated controls include encryption, identity management, endpoint protection and privileged access controls.
The filing also describes vulnerability assessments, penetration testing and red teaming exercises, in which simulated adversarial activity tests the effectiveness of security controls. These measures are part of the company's stated approach to identifying and managing cyber risk.
An Isolated Recovery Environment provides a separate recovery setup with air-gapped infrastructure and immutable backups. According to the RHP, it is intended to help restore business-critical applications when a cyber incident requires activation of that environment.
The presence of these controls explains the framework NSE has disclosed. It does not, by itself, prove that every control will work in every future incident.
How does disaster recovery fit into the picture?
NSE's primary data centre is in Mumbai, with a disaster recovery data centre in Chennai. A near data centre close to the primary site replicates data in real time, targeting near-zero data loss.
The RHP says the fully mirrored disaster recovery site enables a switchover in under 45 minutes. NSE also reports conducting full live operations from that site twice a year, supplemented by mock drills.
These are disclosed infrastructure capabilities and operating practices. They should not be interpreted as a report that the May 2025 website incident required a Chennai switchover, because the RHP does not say that occurred.
Why does this disclosure matter for the exchange business?
NSE's digital systems support trading, clearing, settlement, market data and the handling of confidential information. The RHP consequently treats availability, integrity and security as relevant to both its own operations and wider market confidence.
The May 2025 incident provides a concrete measure of attack traffic while preserving a narrower account of the observed effect. The company reported a slowed website page and no material operational impact. Its broader disclosures explain why cybersecurity and recovery capacity remain operating requirements even when one recorded attack does not materially disrupt the market.

